Key points

  • Brevo says an attacker exploited a SAML SSO authorization flaw to access 138 client accounts before the route was closed.
  • Trezor says a fraudulent security email reached about 347,000 newsletter subscribers and roughly 2,500 people opened its link before takedown.
  • Trezor says its wallets and account systems were not breached, but affected recipients should treat follow-up emails with caution.

Email platform Brevo has disclosed an authorization flaw in its SAML single sign-on system that allowed an attacker to cross organizational boundaries and reach 138 client accounts. The incident enabled phishing campaigns from legitimate sending infrastructure, including a fake security alert delivered to roughly 347,000 Trezor newsletter subscribers.

How the Brevo access-control failure worked

Brevo said the attacker created an account, enabled single sign-on and invited legitimate Brevo users into that configuration. The identity-provider login should have opened only the attacker's organization, but an authorization boundary failure instead exposed every organization those invited users could access.

The provider identified the issue at 06:30 UTC on September 10 and closed the access route two hours later, then signed out all platform users. Brevo said six accounts were used to send phishing emails, contacts were exported from 43 accounts and 93 showed no meaningful activity; its public write-up does not clarify whether those categories overlap.

Trezor email imitated an urgent wallet warning

Trezor said the unauthorized message claimed to concern an entropy vulnerability and directed recipients to download an application that requested their wallet backup. Because it traveled through a genuine marketing system, the email passed normal authentication checks and could appear more credible than a message from a spoofed domain.

The hardware-wallet company said it disabled the malicious domain at the DNS level within 20 minutes. About 2,500 people accessed the link before it stopped working, while the email-sending function was also disabled to prevent additional messages.

Exposure was limited to newsletter addresses

Trezor said no wallet, product or customer-account system was compromised and that Brevo held only opt-in newsletter email addresses, not passwords or wallet data. It could not confirm whether its entire list was exported, so the company is treating all approximately 347,000 addresses as potentially known to the attacker and reusable in later phishing attempts.

Cointelegraph reported that BitBox and crypto tax platform CoinTracking also warned about fraudulent emails distributed through Brevo accounts. BitBox said it had found no evidence of compromised company credentials, disclosed recovery phrases or lost funds, but was awaiting provider logs and treating its subscriber list cautiously.

What affected wallet users should do

Recipients should not follow links or install software from the message, and should delete it. A hardware-wallet recovery phrase should be entered only on the wallet device during a legitimate recovery process, never into an application, webpage or email form.

Trezor says merely opening the disabled link does not expose funds, but anyone who entered a wallet backup should move assets immediately to a newly created wallet with a different recovery phrase. Users should navigate to the company's official site or wallet software directly rather than relying on links inside unexpected alerts.

Brevo closes the route and prepares a permanent fix

Brevo said the attacker no longer had access after the September 10 containment and that it had disabled links in the fraudulent emails. The company is deploying a permanent control intended to restrict each SSO login to the organization that owns the configuration, while contacting affected customers with account-specific details.

Why the incident matters

The episode did not breach cryptocurrency wallets directly, but it demonstrates how a trusted communications supplier can become a route to high-impact social engineering. For self-custody users, authenticated-looking email is not proof that a request is safe; no legitimate support message should ask for a recovery phrase.

Sources

AI-generated editorial image; not a photograph of the reported event. Prepared with AI assistance and source verification.